CVE-2026-2463

MEDIUM

Unauthorized access to invite ID during team creation

Title source: cna
STIX 2.1

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
MMSA-2025-00565
https://mattermost.com/security-updates

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (10)
mattermost/mattermost 0 - 8.0.0-20260105134819-cc427af41b2aGo
Mattermost/Mattermost 10.11.0 - 10.11.10
Mattermost/Mattermost 10.11.11
Mattermost/Mattermost 11.2.0 - 11.2.2
Mattermost/Mattermost 11.2.3
Mattermost/Mattermost 11.3.0
Mattermost/Mattermost 11.3.1
Mattermost/Mattermost 11.4.0
mattermost/mattermost-server 0 - 5.3.2-0.20260105134819-cc427af41b2aGo
mattermost/mattermost_server 10.11.0 - 10.11.11
Published Mar 16, 2026
Tracked Since Mar 16, 2026